<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Traffic Not Returning Via IPSec Tunnels in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/https-traffic-not-returning-via-ipsec-tunnels/m-p/559204#M113413</link>
    <description>&lt;P&gt;We worked with an engineer today, and again, I don't know anything about PAN software, but we had to setup the Proxy IDs. Once we setup Proxy IDs for the remote side, everything starting working.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Sep 2023 18:45:34 GMT</pubDate>
    <dc:creator>coltsfanatic07</dc:creator>
    <dc:date>2023-09-22T18:45:34Z</dc:date>
    <item>
      <title>HTTPS Traffic Not Returning Via IPSec Tunnels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/https-traffic-not-returning-via-ipsec-tunnels/m-p/558821#M113351</link>
      <description>&lt;P&gt;I have a customer who is using PAN appliances and we have a valid IPSec tunnel to a cloud provider. Traffic is fine for SSH and ICMP traffic in both directions. However, when we send HTTPS traffic across the tunnel the firewall logs suggest no bytes received and nothing past the SYN going out (we see no ACK etc.). From the client perspective it results in a timeout obviously.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To troubleshoot, we setup another IPSEC tunnel from another cloud network to confirm that the remote side of the tunnel was not preventing return traffic. Down to using the same subnets etc with no changes made to the remote side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems to me that means there has to be a configuration issue of some sort on the PAN side. Any advice as to what I could check?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 14:13:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/https-traffic-not-returning-via-ipsec-tunnels/m-p/558821#M113351</guid>
      <dc:creator>coltsfanatic07</dc:creator>
      <dc:date>2023-09-20T14:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Traffic Not Returning Via IPSec Tunnels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/https-traffic-not-returning-via-ipsec-tunnels/m-p/558822#M113352</link>
      <description>&lt;P&gt;Maybe one additional relevant piece of information, is the https traffic is ultimately a public ip address. So the intent is a specific CIDR is going across the tunnel and then being routed to the appropriate service on the remote side, but returning back through the tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Again, we have verified the remote side works as intended via a cloud to cloud VPN connection.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 14:21:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/https-traffic-not-returning-via-ipsec-tunnels/m-p/558822#M113352</guid>
      <dc:creator>coltsfanatic07</dc:creator>
      <dc:date>2023-09-20T14:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Traffic Not Returning Via IPSec Tunnels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/https-traffic-not-returning-via-ipsec-tunnels/m-p/559204#M113413</link>
      <description>&lt;P&gt;We worked with an engineer today, and again, I don't know anything about PAN software, but we had to setup the Proxy IDs. Once we setup Proxy IDs for the remote side, everything starting working.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 18:45:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/https-traffic-not-returning-via-ipsec-tunnels/m-p/559204#M113413</guid>
      <dc:creator>coltsfanatic07</dc:creator>
      <dc:date>2023-09-22T18:45:34Z</dc:date>
    </item>
  </channel>
</rss>

